On August 26, 2015, the Department of Defense (“DoD”) issued an interim rule, effective immediately, that revises network security requirements applicable to DoD contractors and introduces new cloud computing provision that reflect current DoD policy. The interim rule, which implements sections of the FY13 and FY15 National Defense Authorization Acts, comes on the heels of the massive breach of Office of Personnel Management systems that compromised the personal data of more than 21 million federal employees. The new and revised requirements apply to cyber incidents on unclassified information systems – breaches of classified systems will continue to be reported in accordance with the National Industrial Security Program Operating Manual. The interim rule also implements DoD policies and procedures applicable to the procurement of contracting for cloud computing services.
The rule includes five contract clauses relevant to contractors and subcontractors providing cloud computing to DoD or who are handling controlled unclassified DoD information on their systems. All five apply to commercial item contracts.Continue Reading DoD Contractors Beware – New Network Penetration Reporting and Cloud Services Requirements Are Here
